{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-36961","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-30T15:25:07.081Z","datePublished":"2024-06-03T07:49:59.621Z","dateUpdated":"2026-08-05T11:32:15.760Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:32:15.760Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/debugfs: Fix two locking issues with thermal zone debug\n\nWith the current thermal zone locking arrangement in the debugfs code,\nuser space can open the \"mitigations\" file for a thermal zone before\nthe zone's debugfs pointer is set which will result in a NULL pointer\ndereference in tze_seq_start().\n\nMoreover, thermal_debug_tz_remove() is not called under the thermal\nzone lock, so it can run in parallel with the other functions accessing\nthe thermal zone's struct thermal_debugfs object.  Then, it may clear\ntz->debugfs after one of those functions has checked it and the\nstruct thermal_debugfs object may be freed prematurely.\n\nTo address the first problem, pass a pointer to the thermal zone's\nstruct thermal_debugfs object to debugfs_create_file() in\nthermal_debug_tz_add() and make tze_seq_start(), tze_seq_next(),\ntze_seq_stop(), and tze_seq_show() retrieve it from s->private\ninstead of a pointer to the thermal zone object.  This will ensure\nthat tz_debugfs will be valid across the \"mitigations\" file accesses\nuntil thermal_debugfs_remove_id() called by thermal_debug_tz_remove()\nremoves that file.\n\nTo address the second problem, use tz->lock in thermal_debug_tz_remove()\naround the tz->debugfs value check (in case the same thermal zone is\nremoved at the same time in two different threads) and its reset to NULL.\n\nCc :6.8+ <stable@vger.kernel.org> # 6.8+"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerability is reached only by opening and reading the per-zone `mitigations` file under /sys/kernel/debug/thermal/thermal_zones/, which requires local access to the machine. There is no network or remote-peer data path into thermal_debugfs.c.\nAC:L - The attacker fully controls the reader side of the race and can spin on open()/read() of the mitigations file indefinitely, while zone add/remove (driver bind/unbind, module load/unload, hotplug, suspend/resume) recurs during normal operation and is directly triggerable by anyone able to unbind the thermal driver. The UAF window spans the whole episode-list teardown and the NULL-deref window spans from `tz->debugfs = NULL` until `debugfs_remove()`, so no condition outside the attacker's influence is needed.\nPR:L - Exploitation needs only a local account with read access to the thermal debugfs entry; on the embedded, Android and appliance builds where CONFIG_THERMAL_DEBUGFS is actually enabled, debugfs is routinely mounted with ownership/permissions relaxed for non-root thermal and telemetry daemons. No capability check exists in the code path itself, so a low-privileged local context is sufficient.\nUI:N - The attacker triggers the bug entirely from their own process by reading the debugfs file; no victim action, mount, or file-open by another user is required.\nS:U - The corruption and its consequences are confined to the kernel of the same host, with no crossing of a VM, IOMMU, or other security-authority boundary. This is standard in-kernel memory corruption.\nC:H - The use-after-free lets a reallocated ~576-byte slab object be walked as the `tz_episodes` list, and tze_seq_show() formats fields reached through those attacker-influenced pointers straight into the seq_file returned to userspace, giving an arbitrary-read/kernel-memory-disclosure primitive.\nI:H - After the free, mutex_lock()/mutex_unlock() and the list operations write into the freed allocation, so heap spraying gives control over adjacent/reallocated kernel objects and a write primitive usable for control-flow hijacking and privilege escalation.\nA:H - Both defects reliably crash the kernel — an unconditional mutex_lock() on a NULL tz->debugfs, and locking/list traversal of freed memory — producing an oops or panic, and the UAF can also deadlock on a destroyed mutex."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/thermal/thermal_debugfs.c"],"versions":[{"version":"7ef01f228c9f54c6260319858be138a8a7e9e704","lessThan":"6c57bdd0505422d5ccd2df541d993aec978c842e","status":"affected","versionType":"git"},{"version":"7ef01f228c9f54c6260319858be138a8a7e9e704","lessThan":"c7f7c37271787a7f77d7eedc132b0b419a76b4c8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/thermal/thermal_debugfs.c"],"versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","status":"unaffected","versionType":"semver"},{"version":"6.8.10","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.8.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6c57bdd0505422d5ccd2df541d993aec978c842e"},{"url":"https://git.kernel.org/stable/c/c7f7c37271787a7f77d7eedc132b0b419a76b4c8"}],"title":"thermal/debugfs: Fix two locking issues with thermal zone debug","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T03:43:50.481Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/6c57bdd0505422d5ccd2df541d993aec978c842e","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/c7f7c37271787a7f77d7eedc132b0b419a76b4c8","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-36961","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T17:15:32.309097Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-11T17:34:59.071Z"}}]}}